service.cpp revision 0828676dff618c8ecc9852cb319543570b3a2e72
1bac3299720623f4226bca103b26260052732ad30Tom Cherry/* 2bac3299720623f4226bca103b26260052732ad30Tom Cherry * Copyright (C) 2015 The Android Open Source Project 3bac3299720623f4226bca103b26260052732ad30Tom Cherry * 4bac3299720623f4226bca103b26260052732ad30Tom Cherry * Licensed under the Apache License, Version 2.0 (the "License"); 5bac3299720623f4226bca103b26260052732ad30Tom Cherry * you may not use this file except in compliance with the License. 6bac3299720623f4226bca103b26260052732ad30Tom Cherry * You may obtain a copy of the License at 7bac3299720623f4226bca103b26260052732ad30Tom Cherry * 8bac3299720623f4226bca103b26260052732ad30Tom Cherry * http://www.apache.org/licenses/LICENSE-2.0 9bac3299720623f4226bca103b26260052732ad30Tom Cherry * 10bac3299720623f4226bca103b26260052732ad30Tom Cherry * Unless required by applicable law or agreed to in writing, software 11bac3299720623f4226bca103b26260052732ad30Tom Cherry * distributed under the License is distributed on an "AS IS" BASIS, 12bac3299720623f4226bca103b26260052732ad30Tom Cherry * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 13bac3299720623f4226bca103b26260052732ad30Tom Cherry * See the License for the specific language governing permissions and 14bac3299720623f4226bca103b26260052732ad30Tom Cherry * limitations under the License. 15bac3299720623f4226bca103b26260052732ad30Tom Cherry */ 16bac3299720623f4226bca103b26260052732ad30Tom Cherry 17bac3299720623f4226bca103b26260052732ad30Tom Cherry#include "service.h" 18bac3299720623f4226bca103b26260052732ad30Tom Cherry 19bac3299720623f4226bca103b26260052732ad30Tom Cherry#include <fcntl.h> 209605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes#include <inttypes.h> 2124b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes#include <linux/securebits.h> 221b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes#include <sched.h> 231b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes#include <sys/mount.h> 241b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes#include <sys/prctl.h> 25081705c258efbe938d71c2022528d809fa6d42c5Vitalii Tomkiv#include <sys/resource.h> 26bac3299720623f4226bca103b26260052732ad30Tom Cherry#include <sys/stat.h> 27081705c258efbe938d71c2022528d809fa6d42c5Vitalii Tomkiv#include <sys/time.h> 28bac3299720623f4226bca103b26260052732ad30Tom Cherry#include <sys/types.h> 29b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET#include <sys/wait.h> 30bac3299720623f4226bca103b26260052732ad30Tom Cherry#include <termios.h> 31af9ba4dc6ca98e136e887b0baa59b72fb8302dd3Dan Albert#include <unistd.h> 32bac3299720623f4226bca103b26260052732ad30Tom Cherry 33bac3299720623f4226bca103b26260052732ad30Tom Cherry#include <selinux/selinux.h> 34bac3299720623f4226bca103b26260052732ad30Tom Cherry 354f71319df011d796a60a43fc1bc68e16fbf7d321Elliott Hughes#include <android-base/file.h> 36da46b392f10d2809b5696632f67485f272ec5698Elliott Hughes#include <android-base/parseint.h> 374f71319df011d796a60a43fc1bc68e16fbf7d321Elliott Hughes#include <android-base/stringprintf.h> 38f86b5a6b90619e02d1d034ef7b0adc3b439f4abbElliott Hughes#include <android-base/strings.h> 39081705c258efbe938d71c2022528d809fa6d42c5Vitalii Tomkiv#include <system/thread_defs.h> 40bac3299720623f4226bca103b26260052732ad30Tom Cherry 41f7e79b99c1e9e3128dd9921871f7740bebb755e6Collin Mulliner#include <processgroup/processgroup.h> 42f7e79b99c1e9e3128dd9921871f7740bebb755e6Collin Mulliner 43bac3299720623f4226bca103b26260052732ad30Tom Cherry#include "action.h" 44bac3299720623f4226bca103b26260052732ad30Tom Cherry#include "init.h" 45bac3299720623f4226bca103b26260052732ad30Tom Cherry#include "init_parser.h" 46bac3299720623f4226bca103b26260052732ad30Tom Cherry#include "log.h" 47bac3299720623f4226bca103b26260052732ad30Tom Cherry#include "property_service.h" 48bac3299720623f4226bca103b26260052732ad30Tom Cherry#include "util.h" 49bac3299720623f4226bca103b26260052732ad30Tom Cherry 50da46b392f10d2809b5696632f67485f272ec5698Elliott Hughesusing android::base::ParseInt; 51b7349902a945903f9e36a569051f5131beb0bc24Tom Cherryusing android::base::StringPrintf; 52b7349902a945903f9e36a569051f5131beb0bc24Tom Cherryusing android::base::WriteStringToFile; 53b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 54344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obesstatic std::string ComputeContextFromExecutable(std::string& service_name, 55344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes const std::string& service_path) { 56344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes std::string computed_context; 57344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes 58344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes char* raw_con = nullptr; 59344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes char* raw_filecon = nullptr; 60344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes 61344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes if (getcon(&raw_con) == -1) { 62344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes LOG(ERROR) << "could not get context while starting '" << service_name << "'"; 63344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes return ""; 64344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes } 65344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes std::unique_ptr<char> mycon(raw_con); 66344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes 67344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes if (getfilecon(service_path.c_str(), &raw_filecon) == -1) { 68344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes LOG(ERROR) << "could not get file context while starting '" << service_name << "'"; 69344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes return ""; 70344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes } 71344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes std::unique_ptr<char> filecon(raw_filecon); 72344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes 73344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes char* new_con = nullptr; 74344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes int rc = security_compute_create(mycon.get(), filecon.get(), 75344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes string_to_security_class("process"), &new_con); 76344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes if (rc == 0) { 77344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes computed_context = new_con; 78344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes free(new_con); 79344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes } 80344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes if (rc == 0 && computed_context == mycon.get()) { 81344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes LOG(ERROR) << "service " << service_name << " does not have a SELinux domain defined"; 82344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes return ""; 83344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes } 84344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes if (rc < 0) { 85344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes LOG(ERROR) << "could not get context while starting '" << service_name << "'"; 86344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes return ""; 87344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes } 88344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes return computed_context; 89344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes} 90344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes 911b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obesstatic void SetUpPidNamespace(const std::string& service_name) { 921b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes constexpr unsigned int kSafeFlags = MS_NODEV | MS_NOEXEC | MS_NOSUID; 931b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes 941b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes // It's OK to LOG(FATAL) in this function since it's running in the first 951b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes // child process. 961b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes if (mount("", "/proc", "proc", kSafeFlags | MS_REMOUNT, "") == -1) { 97e18e7e5c43c39677c6d49f8f76893d720f90b4fbElliott Hughes PLOG(FATAL) << "couldn't remount(/proc) for " << service_name; 981b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes } 991b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes 1001b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes if (prctl(PR_SET_NAME, service_name.c_str()) == -1) { 101e18e7e5c43c39677c6d49f8f76893d720f90b4fbElliott Hughes PLOG(FATAL) << "couldn't set name for " << service_name; 1021b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes } 1031b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes 1041b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes pid_t child_pid = fork(); 1051b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes if (child_pid == -1) { 106e18e7e5c43c39677c6d49f8f76893d720f90b4fbElliott Hughes PLOG(FATAL) << "couldn't fork init inside the PID namespace for " << service_name; 1071b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes } 1081b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes 1091b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes if (child_pid > 0) { 1101b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes // So that we exit with the right status. 1111b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes static int init_exitstatus = 0; 1121b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes signal(SIGTERM, [](int) { _exit(init_exitstatus); }); 1131b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes 1141b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes pid_t waited_pid; 1151b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes int status; 1161b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes while ((waited_pid = wait(&status)) > 0) { 1171b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes // This loop will end when there are no processes left inside the 1181b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes // PID namespace or when the init process inside the PID namespace 1191b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes // gets a signal. 1201b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes if (waited_pid == child_pid) { 1211b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes init_exitstatus = status; 1221b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes } 1231b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes } 1241b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes if (!WIFEXITED(init_exitstatus)) { 1251b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes _exit(EXIT_FAILURE); 1261b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes } 1271b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes _exit(WEXITSTATUS(init_exitstatus)); 1281b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes } 1291b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes} 1301b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes 131344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obesstatic void ExpandArgs(const std::vector<std::string>& args, std::vector<char*>* strs) { 132344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes std::vector<std::string> expanded_args; 133344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes expanded_args.resize(args.size()); 134344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes strs->push_back(const_cast<char*>(args[0].c_str())); 135344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes for (std::size_t i = 1; i < args.size(); ++i) { 136344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes if (!expand_props(args[i], &expanded_args[i])) { 137344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes LOG(FATAL) << args[0] << ": cannot expand '" << args[i] << "'"; 138344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes } 139344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes strs->push_back(const_cast<char*>(expanded_args[i].c_str())); 140344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes } 141344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes strs->push_back(nullptr); 142344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes} 143344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes 144bac3299720623f4226bca103b26260052732ad30Tom CherryServiceEnvironmentInfo::ServiceEnvironmentInfo() { 145bac3299720623f4226bca103b26260052732ad30Tom Cherry} 146bac3299720623f4226bca103b26260052732ad30Tom Cherry 147bac3299720623f4226bca103b26260052732ad30Tom CherryServiceEnvironmentInfo::ServiceEnvironmentInfo(const std::string& name, 148bac3299720623f4226bca103b26260052732ad30Tom Cherry const std::string& value) 149bac3299720623f4226bca103b26260052732ad30Tom Cherry : name(name), value(value) { 150bac3299720623f4226bca103b26260052732ad30Tom Cherry} 151bac3299720623f4226bca103b26260052732ad30Tom Cherry 152bac3299720623f4226bca103b26260052732ad30Tom CherryService::Service(const std::string& name, const std::string& classname, 153bac3299720623f4226bca103b26260052732ad30Tom Cherry const std::vector<std::string>& args) 1549605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes : name_(name), classname_(classname), flags_(0), pid_(0), 1559605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes crash_count_(0), uid_(0), gid_(0), namespace_flags_(0), 1561b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes seclabel_(""), ioprio_class_(IoSchedClass_NONE), ioprio_pri_(0), 157310f6704d0dfe9ca4cfb153ce8e4212cc7596190Marco Nelissen priority_(0), oom_score_adjust_(-1000), args_(args) { 158bac3299720623f4226bca103b26260052732ad30Tom Cherry onrestart_.InitSingleTrigger("onrestart"); 159bac3299720623f4226bca103b26260052732ad30Tom Cherry} 160bac3299720623f4226bca103b26260052732ad30Tom Cherry 161bac3299720623f4226bca103b26260052732ad30Tom CherryService::Service(const std::string& name, const std::string& classname, 1621b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes unsigned flags, uid_t uid, gid_t gid, 16324b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes const std::vector<gid_t>& supp_gids, 16424b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes const CapSet& capabilities, unsigned namespace_flags, 1651b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes const std::string& seclabel, 1661b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes const std::vector<std::string>& args) 1671b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes : name_(name), classname_(classname), flags_(flags), pid_(0), 1689605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes crash_count_(0), uid_(uid), gid_(gid), 16924b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes supp_gids_(supp_gids), capabilities_(capabilities), 17024b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes namespace_flags_(namespace_flags), seclabel_(seclabel), 17124b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes ioprio_class_(IoSchedClass_NONE), ioprio_pri_(0), priority_(0), 17224b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes oom_score_adjust_(-1000), args_(args) { 173bac3299720623f4226bca103b26260052732ad30Tom Cherry onrestart_.InitSingleTrigger("onrestart"); 174bac3299720623f4226bca103b26260052732ad30Tom Cherry} 175bac3299720623f4226bca103b26260052732ad30Tom Cherry 176bac3299720623f4226bca103b26260052732ad30Tom Cherryvoid Service::NotifyStateChange(const std::string& new_state) const { 177bac3299720623f4226bca103b26260052732ad30Tom Cherry if ((flags_ & SVC_EXEC) != 0) { 178bac3299720623f4226bca103b26260052732ad30Tom Cherry // 'exec' commands don't have properties tracking their state. 179bac3299720623f4226bca103b26260052732ad30Tom Cherry return; 180bac3299720623f4226bca103b26260052732ad30Tom Cherry } 181bac3299720623f4226bca103b26260052732ad30Tom Cherry 182b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry std::string prop_name = StringPrintf("init.svc.%s", name_.c_str()); 183bac3299720623f4226bca103b26260052732ad30Tom Cherry property_set(prop_name.c_str(), new_state.c_str()); 1849605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes 1859605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes if (new_state == "running") { 1869605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes uint64_t start_ns = time_started_.time_since_epoch().count(); 187331cf2fb7c16b5b25064f8d2f00284105a9b413fElliott Hughes property_set(StringPrintf("ro.boottime.%s", name_.c_str()).c_str(), 188331cf2fb7c16b5b25064f8d2f00284105a9b413fElliott Hughes StringPrintf("%" PRIu64, start_ns).c_str()); 1899605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes } 190bac3299720623f4226bca103b26260052732ad30Tom Cherry} 191bac3299720623f4226bca103b26260052732ad30Tom Cherry 192ad8e94e017173471e90c704eb7d8de5a14712aa7Elliott Hughesvoid Service::KillProcessGroup(int signal) { 1931e73024653d962b769387dd4c9ff544b6c8b7cc9Elliott Hughes LOG(INFO) << "Sending signal " << signal 1941e73024653d962b769387dd4c9ff544b6c8b7cc9Elliott Hughes << " to service '" << name_ 1951e73024653d962b769387dd4c9ff544b6c8b7cc9Elliott Hughes << "' (pid " << pid_ << ") process group..."; 1961e73024653d962b769387dd4c9ff544b6c8b7cc9Elliott Hughes if (killProcessGroup(uid_, pid_, signal) == -1) { 1971e73024653d962b769387dd4c9ff544b6c8b7cc9Elliott Hughes PLOG(ERROR) << "killProcessGroup(" << uid_ << ", " << pid_ << ", " << signal << ") failed"; 1981e73024653d962b769387dd4c9ff544b6c8b7cc9Elliott Hughes } 1991e73024653d962b769387dd4c9ff544b6c8b7cc9Elliott Hughes if (kill(-pid_, signal) == -1) { 2001e73024653d962b769387dd4c9ff544b6c8b7cc9Elliott Hughes PLOG(ERROR) << "kill(" << pid_ << ", " << signal << ") failed"; 2011e73024653d962b769387dd4c9ff544b6c8b7cc9Elliott Hughes } 202ad8e94e017173471e90c704eb7d8de5a14712aa7Elliott Hughes} 203ad8e94e017173471e90c704eb7d8de5a14712aa7Elliott Hughes 204344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obesvoid Service::SetProcessAttributes() { 20524b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes // Keep capabilites on uid change. 20624b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes if (capabilities_.any() && uid_) { 20724b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes if (prctl(PR_SET_SECUREBITS, SECBIT_KEEP_CAPS | SECBIT_KEEP_CAPS_LOCKED) != 0) { 20824b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes PLOG(FATAL) << "prtcl(PR_SET_KEEPCAPS) failed for " << name_; 20924b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes } 21024b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes } 21124b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes 212e18e7e5c43c39677c6d49f8f76893d720f90b4fbElliott Hughes // TODO: work out why this fails for `console` then upgrade to FATAL. 213e18e7e5c43c39677c6d49f8f76893d720f90b4fbElliott Hughes if (setpgid(0, getpid()) == -1) PLOG(ERROR) << "setpgid failed for " << name_; 214344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes 215344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes if (gid_) { 216344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes if (setgid(gid_) != 0) { 217e18e7e5c43c39677c6d49f8f76893d720f90b4fbElliott Hughes PLOG(FATAL) << "setgid failed for " << name_; 218344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes } 219344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes } 22080960d2a9a6e15931d946cc826dcb3d5bf68ca4fNick Kralevich if (setgroups(supp_gids_.size(), &supp_gids_[0]) != 0) { 22180960d2a9a6e15931d946cc826dcb3d5bf68ca4fNick Kralevich PLOG(FATAL) << "setgroups failed for " << name_; 222344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes } 223344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes if (uid_) { 224344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes if (setuid(uid_) != 0) { 225e18e7e5c43c39677c6d49f8f76893d720f90b4fbElliott Hughes PLOG(FATAL) << "setuid failed for " << name_; 226344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes } 227344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes } 228344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes if (!seclabel_.empty()) { 229344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes if (setexeccon(seclabel_.c_str()) < 0) { 230e18e7e5c43c39677c6d49f8f76893d720f90b4fbElliott Hughes PLOG(FATAL) << "cannot setexeccon('" << seclabel_ << "') for " << name_; 231344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes } 232344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes } 233344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes if (priority_ != 0) { 234344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes if (setpriority(PRIO_PROCESS, 0, priority_) != 0) { 235e18e7e5c43c39677c6d49f8f76893d720f90b4fbElliott Hughes PLOG(FATAL) << "setpriority failed for " << name_; 236344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes } 237344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes } 23824b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes if (capabilities_.any()) { 23924b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes if (!SetCapsForExec(capabilities_)) { 24024b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes LOG(FATAL) << "cannot set capabilities for " << name_; 24124b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes } 24224b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes } 243344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes} 244344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes 245bac3299720623f4226bca103b26260052732ad30Tom Cherrybool Service::Reap() { 246bac3299720623f4226bca103b26260052732ad30Tom Cherry if (!(flags_ & SVC_ONESHOT) || (flags_ & SVC_RESTART)) { 247ad8e94e017173471e90c704eb7d8de5a14712aa7Elliott Hughes KillProcessGroup(SIGKILL); 248bac3299720623f4226bca103b26260052732ad30Tom Cherry } 249bac3299720623f4226bca103b26260052732ad30Tom Cherry 25062767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn // Remove any descriptor resources we may have created. 25162767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn std::for_each(descriptors_.begin(), descriptors_.end(), 25262767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn std::bind(&DescriptorInfo::Clean, std::placeholders::_1)); 253bac3299720623f4226bca103b26260052732ad30Tom Cherry 254bac3299720623f4226bca103b26260052732ad30Tom Cherry if (flags_ & SVC_EXEC) { 255f86b5a6b90619e02d1d034ef7b0adc3b439f4abbElliott Hughes LOG(INFO) << "SVC_EXEC pid " << pid_ << " finished..."; 256bac3299720623f4226bca103b26260052732ad30Tom Cherry return true; 257bac3299720623f4226bca103b26260052732ad30Tom Cherry } 258bac3299720623f4226bca103b26260052732ad30Tom Cherry 259bac3299720623f4226bca103b26260052732ad30Tom Cherry pid_ = 0; 260bac3299720623f4226bca103b26260052732ad30Tom Cherry flags_ &= (~SVC_RUNNING); 261bac3299720623f4226bca103b26260052732ad30Tom Cherry 262bac3299720623f4226bca103b26260052732ad30Tom Cherry // Oneshot processes go into the disabled state on exit, 263bac3299720623f4226bca103b26260052732ad30Tom Cherry // except when manually restarted. 264bac3299720623f4226bca103b26260052732ad30Tom Cherry if ((flags_ & SVC_ONESHOT) && !(flags_ & SVC_RESTART)) { 265bac3299720623f4226bca103b26260052732ad30Tom Cherry flags_ |= SVC_DISABLED; 266bac3299720623f4226bca103b26260052732ad30Tom Cherry } 267bac3299720623f4226bca103b26260052732ad30Tom Cherry 268bac3299720623f4226bca103b26260052732ad30Tom Cherry // Disabled and reset processes do not get restarted automatically. 269bac3299720623f4226bca103b26260052732ad30Tom Cherry if (flags_ & (SVC_DISABLED | SVC_RESET)) { 270bac3299720623f4226bca103b26260052732ad30Tom Cherry NotifyStateChange("stopped"); 271bac3299720623f4226bca103b26260052732ad30Tom Cherry return false; 272bac3299720623f4226bca103b26260052732ad30Tom Cherry } 273bac3299720623f4226bca103b26260052732ad30Tom Cherry 2749605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes // If we crash > 4 times in 4 minutes, reboot into recovery. 2759605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes boot_clock::time_point now = boot_clock::now(); 276bac3299720623f4226bca103b26260052732ad30Tom Cherry if ((flags_ & SVC_CRITICAL) && !(flags_ & SVC_RESTART)) { 2779605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes if (now < time_crashed_ + 4min) { 2789605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes if (++crash_count_ > 4) { 279331cf2fb7c16b5b25064f8d2f00284105a9b413fElliott Hughes LOG(ERROR) << "critical process '" << name_ << "' exited 4 times in 4 minutes"; 280331cf2fb7c16b5b25064f8d2f00284105a9b413fElliott Hughes panic(); 281bac3299720623f4226bca103b26260052732ad30Tom Cherry } 282bac3299720623f4226bca103b26260052732ad30Tom Cherry } else { 283bac3299720623f4226bca103b26260052732ad30Tom Cherry time_crashed_ = now; 2849605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes crash_count_ = 1; 285bac3299720623f4226bca103b26260052732ad30Tom Cherry } 286bac3299720623f4226bca103b26260052732ad30Tom Cherry } 287bac3299720623f4226bca103b26260052732ad30Tom Cherry 288bac3299720623f4226bca103b26260052732ad30Tom Cherry flags_ &= (~SVC_RESTART); 289bac3299720623f4226bca103b26260052732ad30Tom Cherry flags_ |= SVC_RESTARTING; 290bac3299720623f4226bca103b26260052732ad30Tom Cherry 291bac3299720623f4226bca103b26260052732ad30Tom Cherry // Execute all onrestart commands for this service. 292bac3299720623f4226bca103b26260052732ad30Tom Cherry onrestart_.ExecuteAllCommands(); 293bac3299720623f4226bca103b26260052732ad30Tom Cherry 294bac3299720623f4226bca103b26260052732ad30Tom Cherry NotifyStateChange("restarting"); 295bac3299720623f4226bca103b26260052732ad30Tom Cherry return false; 296bac3299720623f4226bca103b26260052732ad30Tom Cherry} 297bac3299720623f4226bca103b26260052732ad30Tom Cherry 298bac3299720623f4226bca103b26260052732ad30Tom Cherryvoid Service::DumpState() const { 299f86b5a6b90619e02d1d034ef7b0adc3b439f4abbElliott Hughes LOG(INFO) << "service " << name_; 300f86b5a6b90619e02d1d034ef7b0adc3b439f4abbElliott Hughes LOG(INFO) << " class '" << classname_ << "'"; 301f86b5a6b90619e02d1d034ef7b0adc3b439f4abbElliott Hughes LOG(INFO) << " exec "<< android::base::Join(args_, " "); 30262767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn std::for_each(descriptors_.begin(), descriptors_.end(), 30362767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn [] (const auto& info) { LOG(INFO) << *info; }); 304bac3299720623f4226bca103b26260052732ad30Tom Cherry} 305bac3299720623f4226bca103b26260052732ad30Tom Cherry 30624b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obesbool Service::ParseCapabilities(const std::vector<std::string>& args, std::string* err) { 30724b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes capabilities_ = 0; 30824b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes 309f3f824ee42892fb69cb0d9b0557cd9c5aed357d2Jorge Lucangeli Obes if (!CapAmbientSupported()) { 310f3f824ee42892fb69cb0d9b0557cd9c5aed357d2Jorge Lucangeli Obes *err = "capabilities requested but the kernel does not support ambient capabilities"; 311f3f824ee42892fb69cb0d9b0557cd9c5aed357d2Jorge Lucangeli Obes return false; 312f3f824ee42892fb69cb0d9b0557cd9c5aed357d2Jorge Lucangeli Obes } 313f3f824ee42892fb69cb0d9b0557cd9c5aed357d2Jorge Lucangeli Obes 314f3f824ee42892fb69cb0d9b0557cd9c5aed357d2Jorge Lucangeli Obes unsigned int last_valid_cap = GetLastValidCap(); 315f3f824ee42892fb69cb0d9b0557cd9c5aed357d2Jorge Lucangeli Obes if (last_valid_cap >= capabilities_.size()) { 316f3f824ee42892fb69cb0d9b0557cd9c5aed357d2Jorge Lucangeli Obes LOG(WARNING) << "last valid run-time capability is larger than CAP_LAST_CAP"; 317f3f824ee42892fb69cb0d9b0557cd9c5aed357d2Jorge Lucangeli Obes } 318f3f824ee42892fb69cb0d9b0557cd9c5aed357d2Jorge Lucangeli Obes 31924b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes for (size_t i = 1; i < args.size(); i++) { 32024b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes const std::string& arg = args[i]; 321f3f824ee42892fb69cb0d9b0557cd9c5aed357d2Jorge Lucangeli Obes int res = LookupCap(arg); 322f3f824ee42892fb69cb0d9b0557cd9c5aed357d2Jorge Lucangeli Obes if (res < 0) { 32324b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes *err = StringPrintf("invalid capability '%s'", arg.c_str()); 32424b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes return false; 32524b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes } 326f3f824ee42892fb69cb0d9b0557cd9c5aed357d2Jorge Lucangeli Obes unsigned int cap = static_cast<unsigned int>(res); // |res| is >= 0. 327f3f824ee42892fb69cb0d9b0557cd9c5aed357d2Jorge Lucangeli Obes if (cap > last_valid_cap) { 328f3f824ee42892fb69cb0d9b0557cd9c5aed357d2Jorge Lucangeli Obes *err = StringPrintf("capability '%s' not supported by the kernel", arg.c_str()); 329f3f824ee42892fb69cb0d9b0557cd9c5aed357d2Jorge Lucangeli Obes return false; 330f3f824ee42892fb69cb0d9b0557cd9c5aed357d2Jorge Lucangeli Obes } 33124b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes capabilities_[cap] = true; 33224b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes } 33324b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes return true; 33424b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes} 33524b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes 336177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obesbool Service::ParseClass(const std::vector<std::string>& args, std::string* err) { 337b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry classname_ = args[1]; 338b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return true; 339b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry} 340bac3299720623f4226bca103b26260052732ad30Tom Cherry 341177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obesbool Service::ParseConsole(const std::vector<std::string>& args, std::string* err) { 342b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry flags_ |= SVC_CONSOLE; 34370daa67062c016eea1a30be2e1de0dcba1d23a13Viorel Suman console_ = args.size() > 1 ? "/dev/" + args[1] : ""; 344b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return true; 345b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry} 346bac3299720623f4226bca103b26260052732ad30Tom Cherry 347177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obesbool Service::ParseCritical(const std::vector<std::string>& args, std::string* err) { 348b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry flags_ |= SVC_CRITICAL; 349b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return true; 350b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry} 351bac3299720623f4226bca103b26260052732ad30Tom Cherry 352177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obesbool Service::ParseDisabled(const std::vector<std::string>& args, std::string* err) { 353b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry flags_ |= SVC_DISABLED; 354b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry flags_ |= SVC_RC_DISABLED; 355b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return true; 356b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry} 357bac3299720623f4226bca103b26260052732ad30Tom Cherry 358177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obesbool Service::ParseGroup(const std::vector<std::string>& args, std::string* err) { 359b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry gid_ = decode_uid(args[1].c_str()); 360b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry for (std::size_t n = 2; n < args.size(); n++) { 361b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry supp_gids_.emplace_back(decode_uid(args[n].c_str())); 362b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry } 363b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return true; 364b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry} 365bac3299720623f4226bca103b26260052732ad30Tom Cherry 366177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obesbool Service::ParsePriority(const std::vector<std::string>& args, std::string* err) { 367da46b392f10d2809b5696632f67485f272ec5698Elliott Hughes priority_ = 0; 368da46b392f10d2809b5696632f67485f272ec5698Elliott Hughes if (!ParseInt(args[1], &priority_, 369dd34ca45ea80c519a579578562e73d5e7f86703bKeun-young Park static_cast<int>(ANDROID_PRIORITY_HIGHEST), // highest is negative 370dd34ca45ea80c519a579578562e73d5e7f86703bKeun-young Park static_cast<int>(ANDROID_PRIORITY_LOWEST))) { 371081705c258efbe938d71c2022528d809fa6d42c5Vitalii Tomkiv *err = StringPrintf("process priority value must be range %d - %d", 372081705c258efbe938d71c2022528d809fa6d42c5Vitalii Tomkiv ANDROID_PRIORITY_HIGHEST, ANDROID_PRIORITY_LOWEST); 373081705c258efbe938d71c2022528d809fa6d42c5Vitalii Tomkiv return false; 374081705c258efbe938d71c2022528d809fa6d42c5Vitalii Tomkiv } 375081705c258efbe938d71c2022528d809fa6d42c5Vitalii Tomkiv return true; 376081705c258efbe938d71c2022528d809fa6d42c5Vitalii Tomkiv} 377081705c258efbe938d71c2022528d809fa6d42c5Vitalii Tomkiv 378177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obesbool Service::ParseIoprio(const std::vector<std::string>& args, std::string* err) { 379da46b392f10d2809b5696632f67485f272ec5698Elliott Hughes if (!ParseInt(args[2], &ioprio_pri_, 0, 7)) { 380b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry *err = "priority value must be range 0 - 7"; 381b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return false; 382b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry } 383b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 384b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry if (args[1] == "rt") { 385b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry ioprio_class_ = IoSchedClass_RT; 386b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry } else if (args[1] == "be") { 387b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry ioprio_class_ = IoSchedClass_BE; 388b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry } else if (args[1] == "idle") { 389b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry ioprio_class_ = IoSchedClass_IDLE; 390b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry } else { 391b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry *err = "ioprio option usage: ioprio <rt|be|idle> <0-7>"; 392b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return false; 393bac3299720623f4226bca103b26260052732ad30Tom Cherry } 394bac3299720623f4226bca103b26260052732ad30Tom Cherry 395b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return true; 396b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry} 397bac3299720623f4226bca103b26260052732ad30Tom Cherry 398177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obesbool Service::ParseKeycodes(const std::vector<std::string>& args, std::string* err) { 399b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry for (std::size_t i = 1; i < args.size(); i++) { 400da46b392f10d2809b5696632f67485f272ec5698Elliott Hughes int code; 401da46b392f10d2809b5696632f67485f272ec5698Elliott Hughes if (ParseInt(args[i], &code)) { 402da46b392f10d2809b5696632f67485f272ec5698Elliott Hughes keycodes_.emplace_back(code); 403da46b392f10d2809b5696632f67485f272ec5698Elliott Hughes } else { 404da46b392f10d2809b5696632f67485f272ec5698Elliott Hughes LOG(WARNING) << "ignoring invalid keycode: " << args[i]; 405da46b392f10d2809b5696632f67485f272ec5698Elliott Hughes } 406bac3299720623f4226bca103b26260052732ad30Tom Cherry } 407b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return true; 408b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry} 409b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 410177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obesbool Service::ParseOneshot(const std::vector<std::string>& args, std::string* err) { 411b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry flags_ |= SVC_ONESHOT; 412b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return true; 413b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry} 414b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 415177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obesbool Service::ParseOnrestart(const std::vector<std::string>& args, std::string* err) { 416b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry std::vector<std::string> str_args(args.begin() + 1, args.end()); 417b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry onrestart_.AddCommand(str_args, "", 0, err); 418b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return true; 419b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry} 420bac3299720623f4226bca103b26260052732ad30Tom Cherry 421177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obesbool Service::ParseNamespace(const std::vector<std::string>& args, std::string* err) { 4221b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes for (size_t i = 1; i < args.size(); i++) { 4231b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes if (args[i] == "pid") { 4241b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes namespace_flags_ |= CLONE_NEWPID; 4251b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes // PID namespaces require mount namespaces. 4261b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes namespace_flags_ |= CLONE_NEWNS; 4271b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes } else if (args[i] == "mnt") { 4281b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes namespace_flags_ |= CLONE_NEWNS; 4291b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes } else { 4301b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes *err = "namespace must be 'pid' or 'mnt'"; 4311b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes return false; 4321b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes } 4331b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes } 4341b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes return true; 4351b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes} 4361b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes 437310f6704d0dfe9ca4cfb153ce8e4212cc7596190Marco Nelissenbool Service::ParseOomScoreAdjust(const std::vector<std::string>& args, std::string* err) { 438da46b392f10d2809b5696632f67485f272ec5698Elliott Hughes if (!ParseInt(args[1], &oom_score_adjust_, -1000, 1000)) { 439310f6704d0dfe9ca4cfb153ce8e4212cc7596190Marco Nelissen *err = "oom_score_adjust value must be in range -1000 - +1000"; 440310f6704d0dfe9ca4cfb153ce8e4212cc7596190Marco Nelissen return false; 441310f6704d0dfe9ca4cfb153ce8e4212cc7596190Marco Nelissen } 442310f6704d0dfe9ca4cfb153ce8e4212cc7596190Marco Nelissen return true; 443310f6704d0dfe9ca4cfb153ce8e4212cc7596190Marco Nelissen} 444310f6704d0dfe9ca4cfb153ce8e4212cc7596190Marco Nelissen 445177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obesbool Service::ParseSeclabel(const std::vector<std::string>& args, std::string* err) { 446b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry seclabel_ = args[1]; 447b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return true; 448b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry} 449b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 450177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obesbool Service::ParseSetenv(const std::vector<std::string>& args, std::string* err) { 451b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry envvars_.emplace_back(args[1], args[2]); 452b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return true; 453b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry} 454b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 45562767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyntemplate <typename T> 45662767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzynbool Service::AddDescriptor(const std::vector<std::string>& args, std::string* err) { 45762767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn int perm = args.size() > 3 ? std::strtoul(args[3].c_str(), 0, 8) : -1; 45862767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn uid_t uid = args.size() > 4 ? decode_uid(args[4].c_str()) : 0; 45962767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn gid_t gid = args.size() > 5 ? decode_uid(args[5].c_str()) : 0; 46062767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn std::string context = args.size() > 6 ? args[6] : ""; 46162767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn 46262767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn auto descriptor = std::make_unique<T>(args[1], args[2], uid, gid, perm, context); 46362767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn 46462767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn auto old = 46562767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn std::find_if(descriptors_.begin(), descriptors_.end(), 46662767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn [&descriptor] (const auto& other) { return descriptor.get() == other.get(); }); 46762767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn 46862767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn if (old != descriptors_.end()) { 46962767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn *err = "duplicate descriptor " + args[1] + " " + args[2]; 47062767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn return false; 47162767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn } 47262767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn 47362767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn descriptors_.emplace_back(std::move(descriptor)); 47462767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn return true; 47562767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn} 47662767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn 47762767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn// name type perm [ uid gid context ] 478177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obesbool Service::ParseSocket(const std::vector<std::string>& args, std::string* err) { 479b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry if (args[2] != "dgram" && args[2] != "stream" && args[2] != "seqpacket") { 480b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry *err = "socket type must be 'dgram', 'stream' or 'seqpacket'"; 481bac3299720623f4226bca103b26260052732ad30Tom Cherry return false; 482bac3299720623f4226bca103b26260052732ad30Tom Cherry } 48362767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn return AddDescriptor<SocketInfo>(args, err); 48462767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn} 485b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 48662767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn// name type perm [ uid gid context ] 48762767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzynbool Service::ParseFile(const std::vector<std::string>& args, std::string* err) { 48862767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn if (args[2] != "r" && args[2] != "w" && args[2] != "rw") { 48962767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn *err = "file type must be 'r', 'w' or 'rw'"; 49062767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn return false; 49162767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn } 49262767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn if ((args[1][0] != '/') || (args[1].find("../") != std::string::npos)) { 49362767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn *err = "file name must not be relative"; 49462767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn return false; 49562767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn } 49662767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn return AddDescriptor<FileInfo>(args, err); 497bac3299720623f4226bca103b26260052732ad30Tom Cherry} 498bac3299720623f4226bca103b26260052732ad30Tom Cherry 499177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obesbool Service::ParseUser(const std::vector<std::string>& args, std::string* err) { 500b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry uid_ = decode_uid(args[1].c_str()); 501b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return true; 502b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry} 503b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 504177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obesbool Service::ParseWritepid(const std::vector<std::string>& args, std::string* err) { 505b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry writepid_files_.assign(args.begin() + 1, args.end()); 506b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return true; 507b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry} 508b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 509177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obesclass Service::OptionParserMap : public KeywordMap<OptionParser> { 510b7349902a945903f9e36a569051f5131beb0bc24Tom Cherrypublic: 511177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes OptionParserMap() { 512b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry } 513b7349902a945903f9e36a569051f5131beb0bc24Tom Cherryprivate: 514b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry Map& map() const override; 515b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry}; 516b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 517177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli ObesService::OptionParserMap::Map& Service::OptionParserMap::map() const { 518b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry constexpr std::size_t kMax = std::numeric_limits<std::size_t>::max(); 519177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes static const Map option_parsers = { 52024b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes {"capabilities", 52124b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes {1, kMax, &Service::ParseCapabilities}}, 522177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes {"class", {1, 1, &Service::ParseClass}}, 523177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes {"console", {0, 1, &Service::ParseConsole}}, 524177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes {"critical", {0, 0, &Service::ParseCritical}}, 525177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes {"disabled", {0, 0, &Service::ParseDisabled}}, 526177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes {"group", {1, NR_SVC_SUPP_GIDS + 1, &Service::ParseGroup}}, 527177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes {"ioprio", {2, 2, &Service::ParseIoprio}}, 528177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes {"priority", {1, 1, &Service::ParsePriority}}, 529177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes {"keycodes", {1, kMax, &Service::ParseKeycodes}}, 530177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes {"oneshot", {0, 0, &Service::ParseOneshot}}, 531177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes {"onrestart", {1, kMax, &Service::ParseOnrestart}}, 532310f6704d0dfe9ca4cfb153ce8e4212cc7596190Marco Nelissen {"oom_score_adjust", 533310f6704d0dfe9ca4cfb153ce8e4212cc7596190Marco Nelissen {1, 1, &Service::ParseOomScoreAdjust}}, 534177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes {"namespace", {1, 2, &Service::ParseNamespace}}, 535177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes {"seclabel", {1, 1, &Service::ParseSeclabel}}, 536177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes {"setenv", {2, 2, &Service::ParseSetenv}}, 537177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes {"socket", {3, 6, &Service::ParseSocket}}, 538978fd0ea254f11f84e38b41a74bbe70c81edc197Mark Salyzyn {"file", {2, 2, &Service::ParseFile}}, 539177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes {"user", {1, 1, &Service::ParseUser}}, 540177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes {"writepid", {1, kMax, &Service::ParseWritepid}}, 541b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry }; 542177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes return option_parsers; 543b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry} 544b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 545177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obesbool Service::ParseLine(const std::vector<std::string>& args, std::string* err) { 546b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry if (args.empty()) { 547b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry *err = "option needed, but not provided"; 548b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return false; 549b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry } 550b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 551177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes static const OptionParserMap parser_map; 552177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes auto parser = parser_map.FindFunction(args[0], args.size() - 1, err); 553b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 554177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes if (!parser) { 555b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return false; 556b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry } 557b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 558177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes return (this->*parser)(args, err); 559b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry} 560b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 561bdeac39a42c1b9c7195ada1c30fe12f94314490fElliott Hughesbool Service::Start() { 562bac3299720623f4226bca103b26260052732ad30Tom Cherry // Starting a service removes it from the disabled or reset state and 563bac3299720623f4226bca103b26260052732ad30Tom Cherry // immediately takes it out of the restarting state if it was in there. 564bac3299720623f4226bca103b26260052732ad30Tom Cherry flags_ &= (~(SVC_DISABLED|SVC_RESTARTING|SVC_RESET|SVC_RESTART|SVC_DISABLED_START)); 565bac3299720623f4226bca103b26260052732ad30Tom Cherry 566bac3299720623f4226bca103b26260052732ad30Tom Cherry // Running processes require no additional work --- if they're in the 567bac3299720623f4226bca103b26260052732ad30Tom Cherry // process of exiting, we've ensured that they will immediately restart 568bac3299720623f4226bca103b26260052732ad30Tom Cherry // on exit, unless they are ONESHOT. 569bac3299720623f4226bca103b26260052732ad30Tom Cherry if (flags_ & SVC_RUNNING) { 570bac3299720623f4226bca103b26260052732ad30Tom Cherry return false; 571bac3299720623f4226bca103b26260052732ad30Tom Cherry } 572bac3299720623f4226bca103b26260052732ad30Tom Cherry 573bac3299720623f4226bca103b26260052732ad30Tom Cherry bool needs_console = (flags_ & SVC_CONSOLE); 57470daa67062c016eea1a30be2e1de0dcba1d23a13Viorel Suman if (needs_console) { 57570daa67062c016eea1a30be2e1de0dcba1d23a13Viorel Suman if (console_.empty()) { 57670daa67062c016eea1a30be2e1de0dcba1d23a13Viorel Suman console_ = default_console; 57770daa67062c016eea1a30be2e1de0dcba1d23a13Viorel Suman } 57870daa67062c016eea1a30be2e1de0dcba1d23a13Viorel Suman 57924ef8601c203a28b85a5e9168e5bada713e6a8f1Adrian Salido // Make sure that open call succeeds to ensure a console driver is 58024ef8601c203a28b85a5e9168e5bada713e6a8f1Adrian Salido // properly registered for the device node 58124ef8601c203a28b85a5e9168e5bada713e6a8f1Adrian Salido int console_fd = open(console_.c_str(), O_RDWR | O_CLOEXEC); 58224ef8601c203a28b85a5e9168e5bada713e6a8f1Adrian Salido if (console_fd < 0) { 58324ef8601c203a28b85a5e9168e5bada713e6a8f1Adrian Salido PLOG(ERROR) << "service '" << name_ << "' couldn't open console '" << console_ << "'"; 58470daa67062c016eea1a30be2e1de0dcba1d23a13Viorel Suman flags_ |= SVC_DISABLED; 58570daa67062c016eea1a30be2e1de0dcba1d23a13Viorel Suman return false; 58670daa67062c016eea1a30be2e1de0dcba1d23a13Viorel Suman } 58724ef8601c203a28b85a5e9168e5bada713e6a8f1Adrian Salido close(console_fd); 588bac3299720623f4226bca103b26260052732ad30Tom Cherry } 589bac3299720623f4226bca103b26260052732ad30Tom Cherry 590bac3299720623f4226bca103b26260052732ad30Tom Cherry struct stat sb; 591bac3299720623f4226bca103b26260052732ad30Tom Cherry if (stat(args_[0].c_str(), &sb) == -1) { 592f86b5a6b90619e02d1d034ef7b0adc3b439f4abbElliott Hughes PLOG(ERROR) << "cannot find '" << args_[0] << "', disabling '" << name_ << "'"; 593bac3299720623f4226bca103b26260052732ad30Tom Cherry flags_ |= SVC_DISABLED; 594bac3299720623f4226bca103b26260052732ad30Tom Cherry return false; 595bac3299720623f4226bca103b26260052732ad30Tom Cherry } 596bac3299720623f4226bca103b26260052732ad30Tom Cherry 597bac3299720623f4226bca103b26260052732ad30Tom Cherry std::string scon; 598bac3299720623f4226bca103b26260052732ad30Tom Cherry if (!seclabel_.empty()) { 599bac3299720623f4226bca103b26260052732ad30Tom Cherry scon = seclabel_; 600bac3299720623f4226bca103b26260052732ad30Tom Cherry } else { 601344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes LOG(INFO) << "computing context for service '" << name_ << "'"; 602344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes scon = ComputeContextFromExecutable(name_, args_[0]); 603344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes if (scon == "") { 604bac3299720623f4226bca103b26260052732ad30Tom Cherry return false; 605bac3299720623f4226bca103b26260052732ad30Tom Cherry } 606bac3299720623f4226bca103b26260052732ad30Tom Cherry } 607bac3299720623f4226bca103b26260052732ad30Tom Cherry 608a285dac9c0b95a0351dfa98dde60c74a1445dc57Wei Wang LOG(INFO) << "starting service '" << name_ << "'..."; 609bac3299720623f4226bca103b26260052732ad30Tom Cherry 6101b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes pid_t pid = -1; 6111b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes if (namespace_flags_) { 612344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes pid = clone(nullptr, nullptr, namespace_flags_ | SIGCHLD, nullptr); 6131b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes } else { 6141b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes pid = fork(); 6151b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes } 6161b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes 617bac3299720623f4226bca103b26260052732ad30Tom Cherry if (pid == 0) { 618bac3299720623f4226bca103b26260052732ad30Tom Cherry umask(077); 619bac3299720623f4226bca103b26260052732ad30Tom Cherry 6201b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes if (namespace_flags_ & CLONE_NEWPID) { 6211b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes // This will fork again to run an init process inside the PID 6221b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes // namespace. 6231b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes SetUpPidNamespace(name_); 6241b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes } 6251b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes 626bac3299720623f4226bca103b26260052732ad30Tom Cherry for (const auto& ei : envvars_) { 627bac3299720623f4226bca103b26260052732ad30Tom Cherry add_environment(ei.name.c_str(), ei.value.c_str()); 628bac3299720623f4226bca103b26260052732ad30Tom Cherry } 629bac3299720623f4226bca103b26260052732ad30Tom Cherry 63062767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn std::for_each(descriptors_.begin(), descriptors_.end(), 63162767fe29f8aaf62470781a3cf419ba11187d178Mark Salyzyn std::bind(&DescriptorInfo::CreateAndPublish, std::placeholders::_1, scon)); 632bac3299720623f4226bca103b26260052732ad30Tom Cherry 6330828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko // See if there were "writepid" instructions to write to files under /dev/cpuset/. 6340828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko auto cpuset_predicate = [](const std::string& path) { 6350828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko return android::base::StartsWith(path, "/dev/cpuset/"); 6360828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko }; 6370828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko auto iter = std::find_if(writepid_files_.begin(), writepid_files_.end(), cpuset_predicate); 6380828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko if (iter == writepid_files_.end()) { 6390828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko // There were no "writepid" instructions for cpusets, check if the system default 6400828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko // cpuset is specified to be used for the process. 6410828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko std::string default_cpuset = property_get("ro.cpuset.default"); 6420828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko if (!default_cpuset.empty()) { 6430828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko // Make sure the cpuset name starts and ends with '/'. 6440828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko // A single '/' means the 'root' cpuset. 6450828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko if (default_cpuset.front() != '/') { 6460828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko default_cpuset.insert(0, 1, '/'); 6470828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko } 6480828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko if (default_cpuset.back() != '/') { 6490828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko default_cpuset.push_back('/'); 6500828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko } 6510828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko writepid_files_.push_back( 6520828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko StringPrintf("/dev/cpuset%stasks", default_cpuset.c_str())); 6530828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko } 6540828676dff618c8ecc9852cb319543570b3a2e72Alex Vakulenko } 655b702b46f688bc3ba7f8dc2d35c6eb25482366c4cAnestis Bechtsoudis std::string pid_str = StringPrintf("%d", getpid()); 656bac3299720623f4226bca103b26260052732ad30Tom Cherry for (const auto& file : writepid_files_) { 657b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry if (!WriteStringToFile(pid_str, file)) { 658f86b5a6b90619e02d1d034ef7b0adc3b439f4abbElliott Hughes PLOG(ERROR) << "couldn't write " << pid_str << " to " << file; 659bac3299720623f4226bca103b26260052732ad30Tom Cherry } 660bac3299720623f4226bca103b26260052732ad30Tom Cherry } 661bac3299720623f4226bca103b26260052732ad30Tom Cherry 662bac3299720623f4226bca103b26260052732ad30Tom Cherry if (ioprio_class_ != IoSchedClass_NONE) { 663bac3299720623f4226bca103b26260052732ad30Tom Cherry if (android_set_ioprio(getpid(), ioprio_class_, ioprio_pri_)) { 664344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes PLOG(ERROR) << "failed to set pid " << getpid() 665f86b5a6b90619e02d1d034ef7b0adc3b439f4abbElliott Hughes << " ioprio=" << ioprio_class_ << "," << ioprio_pri_; 666bac3299720623f4226bca103b26260052732ad30Tom Cherry } 667bac3299720623f4226bca103b26260052732ad30Tom Cherry } 668bac3299720623f4226bca103b26260052732ad30Tom Cherry 669bac3299720623f4226bca103b26260052732ad30Tom Cherry if (needs_console) { 670bac3299720623f4226bca103b26260052732ad30Tom Cherry setsid(); 671bac3299720623f4226bca103b26260052732ad30Tom Cherry OpenConsole(); 672bac3299720623f4226bca103b26260052732ad30Tom Cherry } else { 673bac3299720623f4226bca103b26260052732ad30Tom Cherry ZapStdio(); 674bac3299720623f4226bca103b26260052732ad30Tom Cherry } 675bac3299720623f4226bca103b26260052732ad30Tom Cherry 676344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes // As requested, set our gid, supplemental gids, uid, context, and 677344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes // priority. Aborts on failure. 678344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes SetProcessAttributes(); 679bac3299720623f4226bca103b26260052732ad30Tom Cherry 680bac3299720623f4226bca103b26260052732ad30Tom Cherry std::vector<char*> strs; 681344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes ExpandArgs(args_, &strs); 682bac3536cc949b3af0185e7b8f9b18318b37ac8b0Tom Cherry if (execve(strs[0], (char**) &strs[0], (char**) ENV) < 0) { 683f86b5a6b90619e02d1d034ef7b0adc3b439f4abbElliott Hughes PLOG(ERROR) << "cannot execve('" << strs[0] << "')"; 684bac3299720623f4226bca103b26260052732ad30Tom Cherry } 685bac3299720623f4226bca103b26260052732ad30Tom Cherry 686bac3299720623f4226bca103b26260052732ad30Tom Cherry _exit(127); 687bac3299720623f4226bca103b26260052732ad30Tom Cherry } 688bac3299720623f4226bca103b26260052732ad30Tom Cherry 689bac3299720623f4226bca103b26260052732ad30Tom Cherry if (pid < 0) { 690f86b5a6b90619e02d1d034ef7b0adc3b439f4abbElliott Hughes PLOG(ERROR) << "failed to fork for '" << name_ << "'"; 691bac3299720623f4226bca103b26260052732ad30Tom Cherry pid_ = 0; 692bac3299720623f4226bca103b26260052732ad30Tom Cherry return false; 693bac3299720623f4226bca103b26260052732ad30Tom Cherry } 694bac3299720623f4226bca103b26260052732ad30Tom Cherry 695310f6704d0dfe9ca4cfb153ce8e4212cc7596190Marco Nelissen if (oom_score_adjust_ != -1000) { 696310f6704d0dfe9ca4cfb153ce8e4212cc7596190Marco Nelissen std::string oom_str = StringPrintf("%d", oom_score_adjust_); 697310f6704d0dfe9ca4cfb153ce8e4212cc7596190Marco Nelissen std::string oom_file = StringPrintf("/proc/%d/oom_score_adj", pid); 698310f6704d0dfe9ca4cfb153ce8e4212cc7596190Marco Nelissen if (!WriteStringToFile(oom_str, oom_file)) { 699310f6704d0dfe9ca4cfb153ce8e4212cc7596190Marco Nelissen PLOG(ERROR) << "couldn't write oom_score_adj: " << strerror(errno); 700310f6704d0dfe9ca4cfb153ce8e4212cc7596190Marco Nelissen } 701310f6704d0dfe9ca4cfb153ce8e4212cc7596190Marco Nelissen } 702310f6704d0dfe9ca4cfb153ce8e4212cc7596190Marco Nelissen 7039605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes time_started_ = boot_clock::now(); 704bac3299720623f4226bca103b26260052732ad30Tom Cherry pid_ = pid; 705bac3299720623f4226bca103b26260052732ad30Tom Cherry flags_ |= SVC_RUNNING; 706ad8e94e017173471e90c704eb7d8de5a14712aa7Elliott Hughes 707ad8e94e017173471e90c704eb7d8de5a14712aa7Elliott Hughes errno = -createProcessGroup(uid_, pid_); 708ad8e94e017173471e90c704eb7d8de5a14712aa7Elliott Hughes if (errno != 0) { 709344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes PLOG(ERROR) << "createProcessGroup(" << uid_ << ", " << pid_ << ") failed for service '" 710344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes << name_ << "'"; 711ad8e94e017173471e90c704eb7d8de5a14712aa7Elliott Hughes } 712bac3299720623f4226bca103b26260052732ad30Tom Cherry 713bac3299720623f4226bca103b26260052732ad30Tom Cherry if ((flags_ & SVC_EXEC) != 0) { 714344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes LOG(INFO) << android::base::StringPrintf( 715344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes "SVC_EXEC pid %d (uid %d gid %d+%zu context %s) started; waiting...", pid_, uid_, gid_, 716344d01f99f6049565e4342b4c4202bd9ab96340bJorge Lucangeli Obes supp_gids_.size(), !seclabel_.empty() ? seclabel_.c_str() : "default"); 717bac3299720623f4226bca103b26260052732ad30Tom Cherry } 718bac3299720623f4226bca103b26260052732ad30Tom Cherry 719bac3299720623f4226bca103b26260052732ad30Tom Cherry NotifyStateChange("running"); 720bac3299720623f4226bca103b26260052732ad30Tom Cherry return true; 721bac3299720623f4226bca103b26260052732ad30Tom Cherry} 722bac3299720623f4226bca103b26260052732ad30Tom Cherry 723bac3299720623f4226bca103b26260052732ad30Tom Cherrybool Service::StartIfNotDisabled() { 724bac3299720623f4226bca103b26260052732ad30Tom Cherry if (!(flags_ & SVC_DISABLED)) { 725bac3299720623f4226bca103b26260052732ad30Tom Cherry return Start(); 726bac3299720623f4226bca103b26260052732ad30Tom Cherry } else { 727bac3299720623f4226bca103b26260052732ad30Tom Cherry flags_ |= SVC_DISABLED_START; 728bac3299720623f4226bca103b26260052732ad30Tom Cherry } 729bac3299720623f4226bca103b26260052732ad30Tom Cherry return true; 730bac3299720623f4226bca103b26260052732ad30Tom Cherry} 731bac3299720623f4226bca103b26260052732ad30Tom Cherry 732bac3299720623f4226bca103b26260052732ad30Tom Cherrybool Service::Enable() { 733bac3299720623f4226bca103b26260052732ad30Tom Cherry flags_ &= ~(SVC_DISABLED | SVC_RC_DISABLED); 734bac3299720623f4226bca103b26260052732ad30Tom Cherry if (flags_ & SVC_DISABLED_START) { 735bac3299720623f4226bca103b26260052732ad30Tom Cherry return Start(); 736bac3299720623f4226bca103b26260052732ad30Tom Cherry } 737bac3299720623f4226bca103b26260052732ad30Tom Cherry return true; 738bac3299720623f4226bca103b26260052732ad30Tom Cherry} 739bac3299720623f4226bca103b26260052732ad30Tom Cherry 740bac3299720623f4226bca103b26260052732ad30Tom Cherryvoid Service::Reset() { 741bac3299720623f4226bca103b26260052732ad30Tom Cherry StopOrReset(SVC_RESET); 742bac3299720623f4226bca103b26260052732ad30Tom Cherry} 743bac3299720623f4226bca103b26260052732ad30Tom Cherry 744bac3299720623f4226bca103b26260052732ad30Tom Cherryvoid Service::Stop() { 745bac3299720623f4226bca103b26260052732ad30Tom Cherry StopOrReset(SVC_DISABLED); 746bac3299720623f4226bca103b26260052732ad30Tom Cherry} 747bac3299720623f4226bca103b26260052732ad30Tom Cherry 748b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNETvoid Service::Terminate() { 749b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET flags_ &= ~(SVC_RESTARTING | SVC_DISABLED_START); 750b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET flags_ |= SVC_DISABLED; 751b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET if (pid_) { 752ad8e94e017173471e90c704eb7d8de5a14712aa7Elliott Hughes KillProcessGroup(SIGTERM); 753b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET NotifyStateChange("stopping"); 754b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET } 755b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET} 756b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET 757bac3299720623f4226bca103b26260052732ad30Tom Cherryvoid Service::Restart() { 758bac3299720623f4226bca103b26260052732ad30Tom Cherry if (flags_ & SVC_RUNNING) { 759bac3299720623f4226bca103b26260052732ad30Tom Cherry /* Stop, wait, then start the service. */ 760bac3299720623f4226bca103b26260052732ad30Tom Cherry StopOrReset(SVC_RESTART); 761bac3299720623f4226bca103b26260052732ad30Tom Cherry } else if (!(flags_ & SVC_RESTARTING)) { 762bac3299720623f4226bca103b26260052732ad30Tom Cherry /* Just start the service since it's not running. */ 763bac3299720623f4226bca103b26260052732ad30Tom Cherry Start(); 764bac3299720623f4226bca103b26260052732ad30Tom Cherry } /* else: Service is restarting anyways. */ 765bac3299720623f4226bca103b26260052732ad30Tom Cherry} 766bac3299720623f4226bca103b26260052732ad30Tom Cherry 7679605a945f7a497c0307b512b9cd762f2d23973caElliott Hughesvoid Service::RestartIfNeeded(time_t* process_needs_restart_at) { 7689605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes boot_clock::time_point now = boot_clock::now(); 7699605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes boot_clock::time_point next_start = time_started_ + 5s; 7709605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes if (now > next_start) { 771bac3299720623f4226bca103b26260052732ad30Tom Cherry flags_ &= (~SVC_RESTARTING); 772bac3299720623f4226bca103b26260052732ad30Tom Cherry Start(); 773bac3299720623f4226bca103b26260052732ad30Tom Cherry return; 774bac3299720623f4226bca103b26260052732ad30Tom Cherry } 775bac3299720623f4226bca103b26260052732ad30Tom Cherry 7769605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes time_t next_start_time_t = time(nullptr) + 7779605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes time_t(std::chrono::duration_cast<std::chrono::seconds>(next_start - now).count()); 7789605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes if (next_start_time_t < *process_needs_restart_at || *process_needs_restart_at == 0) { 7799605a945f7a497c0307b512b9cd762f2d23973caElliott Hughes *process_needs_restart_at = next_start_time_t; 780bac3299720623f4226bca103b26260052732ad30Tom Cherry } 781bac3299720623f4226bca103b26260052732ad30Tom Cherry} 782bac3299720623f4226bca103b26260052732ad30Tom Cherry 783ad8e94e017173471e90c704eb7d8de5a14712aa7Elliott Hughes// The how field should be either SVC_DISABLED, SVC_RESET, or SVC_RESTART. 784bac3299720623f4226bca103b26260052732ad30Tom Cherryvoid Service::StopOrReset(int how) { 785ad8e94e017173471e90c704eb7d8de5a14712aa7Elliott Hughes // The service is still SVC_RUNNING until its process exits, but if it has 786ad8e94e017173471e90c704eb7d8de5a14712aa7Elliott Hughes // already exited it shoudn't attempt a restart yet. 787bac3299720623f4226bca103b26260052732ad30Tom Cherry flags_ &= ~(SVC_RESTARTING | SVC_DISABLED_START); 788bac3299720623f4226bca103b26260052732ad30Tom Cherry 789bac3299720623f4226bca103b26260052732ad30Tom Cherry if ((how != SVC_DISABLED) && (how != SVC_RESET) && (how != SVC_RESTART)) { 790ad8e94e017173471e90c704eb7d8de5a14712aa7Elliott Hughes // An illegal flag: default to SVC_DISABLED. 791bac3299720623f4226bca103b26260052732ad30Tom Cherry how = SVC_DISABLED; 792bac3299720623f4226bca103b26260052732ad30Tom Cherry } 793ad8e94e017173471e90c704eb7d8de5a14712aa7Elliott Hughes 794ad8e94e017173471e90c704eb7d8de5a14712aa7Elliott Hughes // If the service has not yet started, prevent it from auto-starting with its class. 795bac3299720623f4226bca103b26260052732ad30Tom Cherry if (how == SVC_RESET) { 796bac3299720623f4226bca103b26260052732ad30Tom Cherry flags_ |= (flags_ & SVC_RC_DISABLED) ? SVC_DISABLED : SVC_RESET; 797bac3299720623f4226bca103b26260052732ad30Tom Cherry } else { 798bac3299720623f4226bca103b26260052732ad30Tom Cherry flags_ |= how; 799bac3299720623f4226bca103b26260052732ad30Tom Cherry } 800bac3299720623f4226bca103b26260052732ad30Tom Cherry 801bac3299720623f4226bca103b26260052732ad30Tom Cherry if (pid_) { 802ad8e94e017173471e90c704eb7d8de5a14712aa7Elliott Hughes KillProcessGroup(SIGKILL); 803bac3299720623f4226bca103b26260052732ad30Tom Cherry NotifyStateChange("stopping"); 804bac3299720623f4226bca103b26260052732ad30Tom Cherry } else { 805bac3299720623f4226bca103b26260052732ad30Tom Cherry NotifyStateChange("stopped"); 806bac3299720623f4226bca103b26260052732ad30Tom Cherry } 807bac3299720623f4226bca103b26260052732ad30Tom Cherry} 808bac3299720623f4226bca103b26260052732ad30Tom Cherry 809bac3299720623f4226bca103b26260052732ad30Tom Cherryvoid Service::ZapStdio() const { 810bac3299720623f4226bca103b26260052732ad30Tom Cherry int fd; 811bac3299720623f4226bca103b26260052732ad30Tom Cherry fd = open("/dev/null", O_RDWR); 812bac3299720623f4226bca103b26260052732ad30Tom Cherry dup2(fd, 0); 813bac3299720623f4226bca103b26260052732ad30Tom Cherry dup2(fd, 1); 814bac3299720623f4226bca103b26260052732ad30Tom Cherry dup2(fd, 2); 815bac3299720623f4226bca103b26260052732ad30Tom Cherry close(fd); 816bac3299720623f4226bca103b26260052732ad30Tom Cherry} 817bac3299720623f4226bca103b26260052732ad30Tom Cherry 818bac3299720623f4226bca103b26260052732ad30Tom Cherryvoid Service::OpenConsole() const { 81970daa67062c016eea1a30be2e1de0dcba1d23a13Viorel Suman int fd = open(console_.c_str(), O_RDWR); 82070daa67062c016eea1a30be2e1de0dcba1d23a13Viorel Suman if (fd == -1) fd = open("/dev/null", O_RDWR); 821bac3299720623f4226bca103b26260052732ad30Tom Cherry ioctl(fd, TIOCSCTTY, 0); 822bac3299720623f4226bca103b26260052732ad30Tom Cherry dup2(fd, 0); 823bac3299720623f4226bca103b26260052732ad30Tom Cherry dup2(fd, 1); 824bac3299720623f4226bca103b26260052732ad30Tom Cherry dup2(fd, 2); 825bac3299720623f4226bca103b26260052732ad30Tom Cherry close(fd); 826bac3299720623f4226bca103b26260052732ad30Tom Cherry} 827bac3299720623f4226bca103b26260052732ad30Tom Cherry 828bac3299720623f4226bca103b26260052732ad30Tom Cherryint ServiceManager::exec_count_ = 0; 829bac3299720623f4226bca103b26260052732ad30Tom Cherry 830bac3299720623f4226bca103b26260052732ad30Tom CherryServiceManager::ServiceManager() { 831bac3299720623f4226bca103b26260052732ad30Tom Cherry} 832bac3299720623f4226bca103b26260052732ad30Tom Cherry 833bac3299720623f4226bca103b26260052732ad30Tom CherryServiceManager& ServiceManager::GetInstance() { 834bac3299720623f4226bca103b26260052732ad30Tom Cherry static ServiceManager instance; 835bac3299720623f4226bca103b26260052732ad30Tom Cherry return instance; 836bac3299720623f4226bca103b26260052732ad30Tom Cherry} 837bac3299720623f4226bca103b26260052732ad30Tom Cherry 838b7349902a945903f9e36a569051f5131beb0bc24Tom Cherryvoid ServiceManager::AddService(std::unique_ptr<Service> service) { 839b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry Service* old_service = FindServiceByName(service->name()); 840b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry if (old_service) { 841f86b5a6b90619e02d1d034ef7b0adc3b439f4abbElliott Hughes LOG(ERROR) << "ignored duplicate definition of service '" << service->name() << "'"; 842b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return; 843bac3299720623f4226bca103b26260052732ad30Tom Cherry } 844b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry services_.emplace_back(std::move(service)); 845bac3299720623f4226bca103b26260052732ad30Tom Cherry} 846bac3299720623f4226bca103b26260052732ad30Tom Cherry 847bac3299720623f4226bca103b26260052732ad30Tom CherryService* ServiceManager::MakeExecOneshotService(const std::vector<std::string>& args) { 848bac3299720623f4226bca103b26260052732ad30Tom Cherry // Parse the arguments: exec [SECLABEL [UID [GID]*] --] COMMAND ARGS... 849bac3299720623f4226bca103b26260052732ad30Tom Cherry // SECLABEL can be a - to denote default 850bac3299720623f4226bca103b26260052732ad30Tom Cherry std::size_t command_arg = 1; 851bac3299720623f4226bca103b26260052732ad30Tom Cherry for (std::size_t i = 1; i < args.size(); ++i) { 852bac3299720623f4226bca103b26260052732ad30Tom Cherry if (args[i] == "--") { 853bac3299720623f4226bca103b26260052732ad30Tom Cherry command_arg = i + 1; 854bac3299720623f4226bca103b26260052732ad30Tom Cherry break; 855bac3299720623f4226bca103b26260052732ad30Tom Cherry } 856bac3299720623f4226bca103b26260052732ad30Tom Cherry } 857bac3299720623f4226bca103b26260052732ad30Tom Cherry if (command_arg > 4 + NR_SVC_SUPP_GIDS) { 858f86b5a6b90619e02d1d034ef7b0adc3b439f4abbElliott Hughes LOG(ERROR) << "exec called with too many supplementary group ids"; 859bac3299720623f4226bca103b26260052732ad30Tom Cherry return nullptr; 860bac3299720623f4226bca103b26260052732ad30Tom Cherry } 861bac3299720623f4226bca103b26260052732ad30Tom Cherry 862bac3299720623f4226bca103b26260052732ad30Tom Cherry if (command_arg >= args.size()) { 863f86b5a6b90619e02d1d034ef7b0adc3b439f4abbElliott Hughes LOG(ERROR) << "exec called without command"; 864bac3299720623f4226bca103b26260052732ad30Tom Cherry return nullptr; 865bac3299720623f4226bca103b26260052732ad30Tom Cherry } 866bac3299720623f4226bca103b26260052732ad30Tom Cherry std::vector<std::string> str_args(args.begin() + command_arg, args.end()); 867bac3299720623f4226bca103b26260052732ad30Tom Cherry 868bac3299720623f4226bca103b26260052732ad30Tom Cherry exec_count_++; 869b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry std::string name = StringPrintf("exec %d (%s)", exec_count_, str_args[0].c_str()); 870bac3299720623f4226bca103b26260052732ad30Tom Cherry unsigned flags = SVC_EXEC | SVC_ONESHOT; 87124b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes CapSet no_capabilities; 8721b3fa3d6506d04570aab60147b0ec743e38c8796Jorge Lucangeli Obes unsigned namespace_flags = 0; 873bac3299720623f4226bca103b26260052732ad30Tom Cherry 874bac3299720623f4226bca103b26260052732ad30Tom Cherry std::string seclabel = ""; 875bac3299720623f4226bca103b26260052732ad30Tom Cherry if (command_arg > 2 && args[1] != "-") { 876bac3299720623f4226bca103b26260052732ad30Tom Cherry seclabel = args[1]; 877bac3299720623f4226bca103b26260052732ad30Tom Cherry } 878bac3299720623f4226bca103b26260052732ad30Tom Cherry uid_t uid = 0; 879bac3299720623f4226bca103b26260052732ad30Tom Cherry if (command_arg > 3) { 880bac3299720623f4226bca103b26260052732ad30Tom Cherry uid = decode_uid(args[2].c_str()); 881bac3299720623f4226bca103b26260052732ad30Tom Cherry } 882bac3299720623f4226bca103b26260052732ad30Tom Cherry gid_t gid = 0; 883bac3299720623f4226bca103b26260052732ad30Tom Cherry std::vector<gid_t> supp_gids; 884bac3299720623f4226bca103b26260052732ad30Tom Cherry if (command_arg > 4) { 885bac3299720623f4226bca103b26260052732ad30Tom Cherry gid = decode_uid(args[3].c_str()); 886bac3299720623f4226bca103b26260052732ad30Tom Cherry std::size_t nr_supp_gids = command_arg - 1 /* -- */ - 4 /* exec SECLABEL UID GID */; 887bac3299720623f4226bca103b26260052732ad30Tom Cherry for (size_t i = 0; i < nr_supp_gids; ++i) { 888bac3299720623f4226bca103b26260052732ad30Tom Cherry supp_gids.push_back(decode_uid(args[4 + i].c_str())); 889bac3299720623f4226bca103b26260052732ad30Tom Cherry } 890bac3299720623f4226bca103b26260052732ad30Tom Cherry } 891bac3299720623f4226bca103b26260052732ad30Tom Cherry 89224b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes std::unique_ptr<Service> svc_p(new Service(name, "default", flags, uid, gid, supp_gids, 89324b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes no_capabilities, namespace_flags, seclabel, 89424b29132a017f7fbfd009c3e6aec499d1b815dbfJorge Lucangeli Obes str_args)); 895bac3299720623f4226bca103b26260052732ad30Tom Cherry if (!svc_p) { 896f86b5a6b90619e02d1d034ef7b0adc3b439f4abbElliott Hughes LOG(ERROR) << "Couldn't allocate service for exec of '" << str_args[0] << "'"; 897bac3299720623f4226bca103b26260052732ad30Tom Cherry return nullptr; 898bac3299720623f4226bca103b26260052732ad30Tom Cherry } 899bac3299720623f4226bca103b26260052732ad30Tom Cherry Service* svc = svc_p.get(); 900bac3299720623f4226bca103b26260052732ad30Tom Cherry services_.push_back(std::move(svc_p)); 901bac3299720623f4226bca103b26260052732ad30Tom Cherry 902bac3299720623f4226bca103b26260052732ad30Tom Cherry return svc; 903bac3299720623f4226bca103b26260052732ad30Tom Cherry} 904bac3299720623f4226bca103b26260052732ad30Tom Cherry 905bac3299720623f4226bca103b26260052732ad30Tom CherryService* ServiceManager::FindServiceByName(const std::string& name) const { 906bac3299720623f4226bca103b26260052732ad30Tom Cherry auto svc = std::find_if(services_.begin(), services_.end(), 907bac3299720623f4226bca103b26260052732ad30Tom Cherry [&name] (const std::unique_ptr<Service>& s) { 908bac3299720623f4226bca103b26260052732ad30Tom Cherry return name == s->name(); 909bac3299720623f4226bca103b26260052732ad30Tom Cherry }); 910bac3299720623f4226bca103b26260052732ad30Tom Cherry if (svc != services_.end()) { 911bac3299720623f4226bca103b26260052732ad30Tom Cherry return svc->get(); 912bac3299720623f4226bca103b26260052732ad30Tom Cherry } 913bac3299720623f4226bca103b26260052732ad30Tom Cherry return nullptr; 914bac3299720623f4226bca103b26260052732ad30Tom Cherry} 915bac3299720623f4226bca103b26260052732ad30Tom Cherry 916bac3299720623f4226bca103b26260052732ad30Tom CherryService* ServiceManager::FindServiceByPid(pid_t pid) const { 917bac3299720623f4226bca103b26260052732ad30Tom Cherry auto svc = std::find_if(services_.begin(), services_.end(), 918bac3299720623f4226bca103b26260052732ad30Tom Cherry [&pid] (const std::unique_ptr<Service>& s) { 919bac3299720623f4226bca103b26260052732ad30Tom Cherry return s->pid() == pid; 920bac3299720623f4226bca103b26260052732ad30Tom Cherry }); 921bac3299720623f4226bca103b26260052732ad30Tom Cherry if (svc != services_.end()) { 922bac3299720623f4226bca103b26260052732ad30Tom Cherry return svc->get(); 923bac3299720623f4226bca103b26260052732ad30Tom Cherry } 924bac3299720623f4226bca103b26260052732ad30Tom Cherry return nullptr; 925bac3299720623f4226bca103b26260052732ad30Tom Cherry} 926bac3299720623f4226bca103b26260052732ad30Tom Cherry 927bac3299720623f4226bca103b26260052732ad30Tom CherryService* ServiceManager::FindServiceByKeychord(int keychord_id) const { 928bac3299720623f4226bca103b26260052732ad30Tom Cherry auto svc = std::find_if(services_.begin(), services_.end(), 929bac3299720623f4226bca103b26260052732ad30Tom Cherry [&keychord_id] (const std::unique_ptr<Service>& s) { 930bac3299720623f4226bca103b26260052732ad30Tom Cherry return s->keychord_id() == keychord_id; 931bac3299720623f4226bca103b26260052732ad30Tom Cherry }); 932bac3299720623f4226bca103b26260052732ad30Tom Cherry 933bac3299720623f4226bca103b26260052732ad30Tom Cherry if (svc != services_.end()) { 934bac3299720623f4226bca103b26260052732ad30Tom Cherry return svc->get(); 935bac3299720623f4226bca103b26260052732ad30Tom Cherry } 936bac3299720623f4226bca103b26260052732ad30Tom Cherry return nullptr; 937bac3299720623f4226bca103b26260052732ad30Tom Cherry} 938bac3299720623f4226bca103b26260052732ad30Tom Cherry 9398f7b9e3d39cdae8363816aa7bcbab0d79fd70ceaChih-Hung Hsiehvoid ServiceManager::ForEachService(const std::function<void(Service*)>& callback) const { 940bac3299720623f4226bca103b26260052732ad30Tom Cherry for (const auto& s : services_) { 941b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET callback(s.get()); 942bac3299720623f4226bca103b26260052732ad30Tom Cherry } 943bac3299720623f4226bca103b26260052732ad30Tom Cherry} 944bac3299720623f4226bca103b26260052732ad30Tom Cherry 945bac3299720623f4226bca103b26260052732ad30Tom Cherryvoid ServiceManager::ForEachServiceInClass(const std::string& classname, 946bac3299720623f4226bca103b26260052732ad30Tom Cherry void (*func)(Service* svc)) const { 947bac3299720623f4226bca103b26260052732ad30Tom Cherry for (const auto& s : services_) { 948bac3299720623f4226bca103b26260052732ad30Tom Cherry if (classname == s->classname()) { 949bac3299720623f4226bca103b26260052732ad30Tom Cherry func(s.get()); 950bac3299720623f4226bca103b26260052732ad30Tom Cherry } 951bac3299720623f4226bca103b26260052732ad30Tom Cherry } 952bac3299720623f4226bca103b26260052732ad30Tom Cherry} 953bac3299720623f4226bca103b26260052732ad30Tom Cherry 954bac3299720623f4226bca103b26260052732ad30Tom Cherryvoid ServiceManager::ForEachServiceWithFlags(unsigned matchflags, 955bac3299720623f4226bca103b26260052732ad30Tom Cherry void (*func)(Service* svc)) const { 956bac3299720623f4226bca103b26260052732ad30Tom Cherry for (const auto& s : services_) { 957bac3299720623f4226bca103b26260052732ad30Tom Cherry if (s->flags() & matchflags) { 958bac3299720623f4226bca103b26260052732ad30Tom Cherry func(s.get()); 959bac3299720623f4226bca103b26260052732ad30Tom Cherry } 960bac3299720623f4226bca103b26260052732ad30Tom Cherry } 961bac3299720623f4226bca103b26260052732ad30Tom Cherry} 962bac3299720623f4226bca103b26260052732ad30Tom Cherry 963b7349902a945903f9e36a569051f5131beb0bc24Tom Cherryvoid ServiceManager::RemoveService(const Service& svc) { 964bac3299720623f4226bca103b26260052732ad30Tom Cherry auto svc_it = std::find_if(services_.begin(), services_.end(), 965bac3299720623f4226bca103b26260052732ad30Tom Cherry [&svc] (const std::unique_ptr<Service>& s) { 966bac3299720623f4226bca103b26260052732ad30Tom Cherry return svc.name() == s->name(); 967bac3299720623f4226bca103b26260052732ad30Tom Cherry }); 968bac3299720623f4226bca103b26260052732ad30Tom Cherry if (svc_it == services_.end()) { 969bac3299720623f4226bca103b26260052732ad30Tom Cherry return; 970bac3299720623f4226bca103b26260052732ad30Tom Cherry } 971bac3299720623f4226bca103b26260052732ad30Tom Cherry 972bac3299720623f4226bca103b26260052732ad30Tom Cherry services_.erase(svc_it); 973bac3299720623f4226bca103b26260052732ad30Tom Cherry} 974bac3299720623f4226bca103b26260052732ad30Tom Cherry 975b7349902a945903f9e36a569051f5131beb0bc24Tom Cherryvoid ServiceManager::DumpState() const { 976b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry for (const auto& s : services_) { 977b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry s->DumpState(); 978b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry } 979b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry} 980b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 981b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNETbool ServiceManager::ReapOneProcess() { 982b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET int status; 983b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET pid_t pid = TEMP_FAILURE_RETRY(waitpid(-1, &status, WNOHANG)); 984b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET if (pid == 0) { 985b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET return false; 986b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET } else if (pid == -1) { 987f86b5a6b90619e02d1d034ef7b0adc3b439f4abbElliott Hughes PLOG(ERROR) << "waitpid failed"; 988b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET return false; 989b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET } 990b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET 991b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET Service* svc = FindServiceByPid(pid); 992b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET 993b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET std::string name; 994b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET if (svc) { 995b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET name = android::base::StringPrintf("Service '%s' (pid %d)", 996b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET svc->name().c_str(), pid); 997b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET } else { 998b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET name = android::base::StringPrintf("Untracked pid %d", pid); 999b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET } 1000b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET 1001b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET if (WIFEXITED(status)) { 1002a285dac9c0b95a0351dfa98dde60c74a1445dc57Wei Wang LOG(INFO) << name << " exited with status " << WEXITSTATUS(status); 1003b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET } else if (WIFSIGNALED(status)) { 1004a285dac9c0b95a0351dfa98dde60c74a1445dc57Wei Wang LOG(INFO) << name << " killed by signal " << WTERMSIG(status); 1005b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET } else if (WIFSTOPPED(status)) { 1006a285dac9c0b95a0351dfa98dde60c74a1445dc57Wei Wang LOG(INFO) << name << " stopped by signal " << WSTOPSIG(status); 1007b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET } else { 1008a285dac9c0b95a0351dfa98dde60c74a1445dc57Wei Wang LOG(INFO) << name << " state changed"; 1009b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET } 1010b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET 1011b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET if (!svc) { 1012b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET return true; 1013b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET } 1014b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET 1015b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET if (svc->Reap()) { 10162d0fdaaafc5d2925b8ef7708a950f6b599892b54Wei Wang stop_waiting_for_exec(); 1017b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET RemoveService(*svc); 1018b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET } 1019b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET 1020b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET return true; 1021b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET} 1022b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET 1023b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNETvoid ServiceManager::ReapAnyOutstandingChildren() { 1024b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET while (ReapOneProcess()) { 1025b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET } 1026b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET} 1027b7e03e82b89a30b09fea88eaf2a5638df1017cf6Bertrand SIMONNET 1028b7349902a945903f9e36a569051f5131beb0bc24Tom Cherrybool ServiceParser::ParseSection(const std::vector<std::string>& args, 1029b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry std::string* err) { 1030b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry if (args.size() < 3) { 1031b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry *err = "services must have a name and a program"; 1032b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return false; 1033b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry } 1034b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 1035b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry const std::string& name = args[1]; 1036b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry if (!IsValidName(name)) { 1037b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry *err = StringPrintf("invalid service name '%s'", name.c_str()); 1038b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return false; 1039b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry } 1040b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 1041b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry std::vector<std::string> str_args(args.begin() + 2, args.end()); 1042b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry service_ = std::make_unique<Service>(name, "default", str_args); 1043b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry return true; 1044b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry} 1045b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 1046b7349902a945903f9e36a569051f5131beb0bc24Tom Cherrybool ServiceParser::ParseLineSection(const std::vector<std::string>& args, 1047b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry const std::string& filename, int line, 1048b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry std::string* err) const { 1049177b27d4f5bfa498cc46aad24d9375d65630bea0Jorge Lucangeli Obes return service_ ? service_->ParseLine(args, err) : false; 1050b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry} 1051b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 1052b7349902a945903f9e36a569051f5131beb0bc24Tom Cherryvoid ServiceParser::EndSection() { 1053b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry if (service_) { 1054b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry ServiceManager::GetInstance().AddService(std::move(service_)); 1055b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry } 1056b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry} 1057b7349902a945903f9e36a569051f5131beb0bc24Tom Cherry 1058b7349902a945903f9e36a569051f5131beb0bc24Tom Cherrybool ServiceParser::IsValidName(const std::string& name) const { 1059b7788fd454da2201c6e48dededa9b11873ef621eElliott Hughes // Property names can be any length, but may only contain certain characters. 1060b7788fd454da2201c6e48dededa9b11873ef621eElliott Hughes // Property values can contain any characters, but may only be a certain length. 1061b7788fd454da2201c6e48dededa9b11873ef621eElliott Hughes // (The latter restriction is needed because `start` and `stop` work by writing 1062b7788fd454da2201c6e48dededa9b11873ef621eElliott Hughes // the service name to the "ctl.start" and "ctl.stop" properties.) 1063b7788fd454da2201c6e48dededa9b11873ef621eElliott Hughes return is_legal_property_name("init.svc." + name) && name.size() <= PROP_VALUE_MAX; 1064bac3299720623f4226bca103b26260052732ad30Tom Cherry} 1065